Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2mhv-gvhq-ff4g

около 4 лет назад

Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mhv-543f-h64j

почти 4 года назад

A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2mhr-7vwh-hrjc

около 4 лет назад

SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mhq-qg26-p24h

больше 4 лет назад

An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.

EPSS: Средний
github логотип

GHSA-2mhq-48gx-32rg

10 месяцев назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore allows Code Injection. This issue affects XStore: from n/a through 9.5.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mhq-3gfj-j2g2

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mhp-j72r-j69f

больше 4 лет назад

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.

EPSS: Низкий
github логотип

GHSA-2mhj-64gr-7wf9

больше 4 лет назад

IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

EPSS: Средний
github логотип

GHSA-2mhj-4m6m-6rj5

9 дней назад

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit copy_from_user() returns the number of bytes not copied as an unsigned residual on failure (1..sizeof(struct fuse_out_header)). fuse_uring_commit stores that residual in ssize_t err, sets req->out.h.error to -EFAULT, then jumps to out: with err still holding the positive residual. err = copy_from_user(&req->out.h, &ent->headers->in_out, sizeof(req->out.h)); if (err) { req->out.h.error = -EFAULT; goto out; /* err is the positive residual */ } ... out: fuse_uring_req_end(ent, req, err); fuse_uring_req_end() then runs if (error) req->out.h.error = error; which overwrites the just-assigned -EFAULT with the positive residual. FUSE callers such as fuse_simple_request() test err < 0 to detect failure, so the positive value is interpreted as success and the caller proceeds with ...

EPSS: Низкий
github логотип

GHSA-2mhh-w6q8-5hxw

больше 7 лет назад

Remote Memory Disclosure in ws

EPSS: Низкий
github логотип

GHSA-2mhh-8chh-jm97

больше 4 лет назад

The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.

EPSS: Низкий
github логотип

GHSA-2mhh-27v7-3vcx

около 3 лет назад

WWBN AVideo command injection vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mhg-3m7f-9876

около 4 лет назад

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mhf-8wh4-g2p3

4 месяца назад

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). The vulnerability is only exploitable if a file upload field is added to the form and the “Saving inquiry data in database” option is enabled.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2mhf-732c-q449

около 4 лет назад

A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.

EPSS: Низкий
github логотип

GHSA-2mhc-xxvw-f39p

около 4 лет назад

Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2mh9-wpgv-7xr8

около 4 лет назад

Jenkins Cloud Foundry Plugin vulnerable to exposure of sensitive information

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mh9-r7m5-wv93

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: crash_dump: don't log dm-crypt key bytes in read_key_from_user_keying When debug logging is enabled, read_key_from_user_keying() logs the first 8 bytes of the key payload and partially exposes the dm-crypt key. Stop logging any key bytes.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mh9-q72v-7c49

почти 4 года назад

H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function edditactionlist.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mh8-mqmp-3xq6

8 месяцев назад

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their WSDesk privileges from limited "Reply Tickets" permissions to full helpdesk administrator capabilities, gaining unauthorized access to ticket management, settings configuration, agent administration, and sensitive customer data.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mhv-gvhq-ff4g

Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mhv-543f-h64j

A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.

CVSS3: 7
1%
Низкий
почти 4 года назад
github логотип
GHSA-2mhr-7vwh-hrjc

SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2mhq-qg26-p24h

An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.

38%
Средний
больше 4 лет назад
github логотип
GHSA-2mhq-48gx-32rg

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore allows Code Injection. This issue affects XStore: from n/a through 9.5.3.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2mhq-3gfj-j2g2

Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mhp-j72r-j69f

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-2mhj-64gr-7wf9

IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

25%
Средний
больше 4 лет назад
github логотип
GHSA-2mhj-4m6m-6rj5

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit copy_from_user() returns the number of bytes not copied as an unsigned residual on failure (1..sizeof(struct fuse_out_header)). fuse_uring_commit stores that residual in ssize_t err, sets req->out.h.error to -EFAULT, then jumps to out: with err still holding the positive residual. err = copy_from_user(&req->out.h, &ent->headers->in_out, sizeof(req->out.h)); if (err) { req->out.h.error = -EFAULT; goto out; /* err is the positive residual */ } ... out: fuse_uring_req_end(ent, req, err); fuse_uring_req_end() then runs if (error) req->out.h.error = error; which overwrites the just-assigned -EFAULT with the positive residual. FUSE callers such as fuse_simple_request() test err < 0 to detect failure, so the positive value is interpreted as success and the caller proceeds with ...

0%
Низкий
9 дней назад
github логотип
GHSA-2mhh-w6q8-5hxw

Remote Memory Disclosure in ws

2%
Низкий
больше 7 лет назад
github логотип
GHSA-2mhh-8chh-jm97

The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2mhh-27v7-3vcx

WWBN AVideo command injection vulnerability

CVSS3: 8.8
6%
Низкий
около 3 лет назад
github логотип
GHSA-2mhg-3m7f-9876

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mhf-8wh4-g2p3

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). The vulnerability is only exploitable if a file upload field is added to the form and the “Saving inquiry data in database” option is enabled.

CVSS3: 8.1
1%
Низкий
4 месяца назад
github логотип
GHSA-2mhf-732c-q449

A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mhc-xxvw-f39p

Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mh9-wpgv-7xr8

Jenkins Cloud Foundry Plugin vulnerable to exposure of sensitive information

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mh9-r7m5-wv93

In the Linux kernel, the following vulnerability has been resolved: crash_dump: don't log dm-crypt key bytes in read_key_from_user_keying When debug logging is enabled, read_key_from_user_keying() logs the first 8 bytes of the key payload and partially exposes the dm-crypt key. Stop logging any key bytes.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2mh9-q72v-7c49

H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function edditactionlist.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2mh8-mqmp-3xq6

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their WSDesk privileges from limited "Reply Tickets" permissions to full helpdesk administrator capabilities, gaining unauthorized access to ticket management, settings configuration, agent administration, and sensitive customer data.

CVSS3: 6.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу